CMS-Senior-Incident Orchestrator
EY
EY
Join EY and build a career that's as unique as you are, leveraging global scale and an inclusive culture to become your best self. Contribute your perspective to enhance EY's success and help build a better working world for everyone.
The Incident Orchestrator plays a crucial role in coordinating and governing the handling of security incidents identified by the Security Operations Center (SOC). This position ensures timely and effective resolution of incidents, acting as a central liaison between various security and IT teams. The role adheres strictly to the enterprise Incident Response Plan and Policy, promoting structured, repeatable, and auditable incident management processes.
Oversee the complete lifecycle of security incidents, from initial escalation through containment, remediation, and final closure. Serve as the primary coordination point for L1/L2 SOC analysts, threat detection specialists, IT teams, and incident response stakeholders. Ensure accurate classification, prioritization, and handling of incidents aligned with the approved Incident Response Policy and severity model. Validate escalated alerts to confirm true positives and assess business impact before initiating response actions. Drive containment and mitigation efforts by collaborating with relevant resolver groups, including endpoint, network, identity, and cloud teams. Manage incident bridges and war rooms during critical incidents, ensuring clear ownership and prompt updates. Accurately document all incident activities in the designated incident management platform. Prepare and deliver comprehensive incident status updates, timelines, and summaries to SOC leadership and stakeholders. Support post-incident reviews (PIRs) by compiling evidence, timelines, and response effectiveness data. Ensure adherence to defined playbooks, runbooks, and SOPs for SOC incident handling. Identify process gaps, recurring issues, and inefficiencies to recommend improvements to SOC and IR leadership. Act as a senior escalation point for complex or ambiguous incidents requiring expert judgment. Review and refine incident response processes and playbooks. Participate in or lead incident response calls and post-incident reviews, contributing to the assessment of response effectiveness and identifying areas for enhancement. Provide guidance and mentorship to junior incident responders.
Demonstrated experience with digital forensics tools and techniques for incident investigation. Proficiency in using SIEM solutions such as Splunk, Microsoft Sentinel, LogScale, Google Chronicle, or IBM QRadar for incident response and analysis. Experience with EDR/XDR platforms including CrowdStrike, Microsoft Defender, SentinelOne, Cortex XSIAM, or Carbon Black. Solid understanding of fundamental security principles, techniques, and technologies like SANS Top 20 Critical Security Controls and OWASP Top 10. Knowledge of attack lifecycles and incident response phases (identify, contain, eradicate, recover). In-depth understanding of network protocols, operating systems, and core security technologies. Proficiency in incident detection and response tools. Familiarity with malware analysis and reverse engineering is advantageous. Competence in scripting languages like Python or PowerShell for task automation. A minimum of 5 years of security-related experience in areas such as Security Operations, Incident Response, and Forensic Investigation is preferred. Possess an analytical mindset with the ability to learn quickly. Willingness to work in a 24/7 operations center environment, including shift work. Strong problem-solving skills to effectively analyze complex incidents. Excellent verbal and written communication skills are essential. A Bachelor's Degree in a relevant Information Technology field is ideal, alongside certifications such as CEH, CHFI, Sec+, ITILv3, GCFA, ECIH, GCIH, or CySA+.
EY Global Delivery Services ( EY GDS)
IT Consulting